Arne Fitzenreiter
00a655fa5c
rootfiles: replace x86_64 with MACHINE
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-08-17 16:47:34 +02:00
Arne Fitzenreiter
bdde6afa76
Unix-syslog: fix rootfile
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-08-17 10:51:18 +02:00
Arne Fitzenreiter
2ea3f4d95f
rootfiles: perl 5.30 needs the autosplit.ix files
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-08-17 10:42:43 +02:00
Arne Fitzenreiter
0eff753d71
rootfile update for all common perl modules.
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-08-16 12:50:19 +02:00
Arne Fitzenreiter
2fa5a87dc0
MIME-Tools: update to 5.509
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-08-16 12:42:01 +02:00
Arne Fitzenreiter
6dac067cfe
perl-Switch: add module
...
perl-Switch was removed from perl core distribution
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-08-16 12:36:20 +02:00
Arne Fitzenreiter
2890ab712e
perl-CGI: add perl-CGI module.
...
perl-CGI was remoced from perl core distribution
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-08-16 12:35:01 +02:00
Arne Fitzenreiter
9680152977
perl: update to 5.30
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-08-16 12:33:40 +02:00
Arne Fitzenreiter
348cc0ddcd
texinfo: update to 6.6
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-08-16 12:17:51 +02:00
Arne Fitzenreiter
7c30831ad2
initskripts: move unbound down after network down
...
this remove a bunch of unbound errors at shutdown because
network down try to reconfigure unbond. (e.g. disable forwarders)
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-08-11 11:09:40 +02:00
Arne Fitzenreiter
10dd2afd6d
sysctl: add seperate sysctl-x86_64.conf and move x86_64 only parameters
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-08-08 09:30:49 +02:00
Arne Fitzenreiter
6836e528e5
u-boot-friendlyarm: add u-boot for nanopi-r1 to boot from eMMC
...
this is a heavy patched version and should replaced when stock
u-boot is able to boot from h3 eMMC.
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-08-06 04:32:22 +00:00
Arne Fitzenreiter
a6859d889e
rpi-firmware: create copy of RPI3 brcm 43430 configfile.
...
the AP21xx need a different config so store the rpi version as backup.
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-07-31 11:03:33 +00:00
Arne Fitzenreiter
53ece8f1f7
kernel: update arm-multi patchset
...
this add FriendlyElec nanopi-r1 devicetree file.
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-07-30 18:27:43 +00:00
Arne Fitzenreiter
fd7c2f3a9e
initskripts: fix i586 rootfile
2019-07-17 13:12:46 +02:00
Arne Fitzenreiter
3ec3329dff
unbound: rework dns-forwader handling
...
add check if red interface has an IPv4 address before test the servers at
red up and simply remove forwarders at down process.
This also fix the hung at dhcpd shutdown.
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-07-16 19:20:48 +02:00
Michael Tremer
acf47bfa80
cloud-init: Import experimental configuration script for Azure
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-07-01 07:53:58 +01:00
Michael Tremer
ffb37e51d4
Rename AWS initscript to cloud-init
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-07-01 07:53:58 +01:00
Matthias Fischer
1c505151cb
nettle: Update to 3.5.1
...
For details see:
https://git.lysator.liu.se/nettle/nettle/blob/master/ChangeLog
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-06-25 08:18:15 +01:00
Michael Tremer
759be5855f
linux: Fix rootfile to ship GeoIP modules
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-06-24 14:39:30 +01:00
Matthias Fischer
f3959d13e8
bind: Update to 9.11.8
...
For Details see:
https://downloads.isc.org/isc/bind9/9.11.8/RELEASE-NOTES-bind-9.11.8.html
"Security Fixes
A race condition could trigger an assertion failure when a large number
of incoming packets were being rejected.
This flaw is disclosed in CVE-2019-6471. [GL #942 ]"
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-06-21 01:39:18 +01:00
Arne Fitzenreiter
70590cef48
Kernel: update to 4.14.128
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-06-19 21:01:29 +02:00
Matthias Fischer
98f55e136f
vim: Update to 8.1
...
Please note:
If this gets merged, the update process must deal with the otherwise remaining
files in '/usr/share/vim74' (~16 MB).
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-06-18 22:34:55 +01:00
Arne Fitzenreiter
15ca18a3d9
Merge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next
2019-06-18 18:42:02 +02:00
Arne Fitzenreiter
82c279a518
kernel: update to 4.14.127
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-06-18 18:41:19 +02:00
Matthias Fischer
2f278de868
unbound: Update to 1.9.2
...
For details see:
https://nlnetlabs.nl/pipermail/unbound-users/2019-June/011632.html
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-06-17 17:39:37 +01:00
Michael Tremer
35f12f2998
Rootfile update
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-06-10 09:58:15 +01:00
Michael Tremer
28093c8376
Rootfile update
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-06-08 11:34:37 +01:00
Michael Tremer
09b9910696
Rootfile update
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-06-07 11:14:11 +01:00
Tim FitzGeorge
a5ba473c15
suricata: correct rule actions in IPS mode
...
In IPS mode rule actions need to be have the action 'drop' for the
protection to work, however this is not appropriate for all rules.
Modify the generator for oinkmaster-modify-sids.conf to leave
rules with the action 'alert' here this is appropriate. Also add
a script to be run on update to correct existing downloaded rules.
Fixes #12086
Signed-off-by: Tim FitzGeorge <ipfr@tfitzgeorge.me.uk >
Tested-by: Peter Müller <peter.mueller@ipfire.org >
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-06-05 12:39:57 +01:00
Michael Tremer
cfbb61a74d
Rootfile update for ARM kernels
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-06-04 23:44:49 +01:00
Michael Tremer
236831c0f9
Rootfile update for gcc on i586
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-06-04 23:41:59 +01:00
Matthias Fischer
83d4264eba
rrdtool: Update to 1.7.2
...
For details see:
https://oss.oetiker.ch/rrdtool/pub/CHANGES
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-06-04 23:31:11 +01:00
Michael Tremer
c7def60649
Rootfile update
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-06-03 09:20:05 +01:00
Michael Tremer
f62f432a27
openssl: Update to 1.1.1c
...
Fixes CVE-2019-1543
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-05-29 13:51:48 +01:00
Michael Tremer
7b6d2972e3
strongswan: Update to 5.8.0
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-05-28 13:05:50 +01:00
Michael Tremer
71ff23c765
Rootfile update
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-05-28 11:41:46 +01:00
Michael Tremer
81544f8884
hyperscan: Move rootfiles to arch directories
...
This package is only compiled on x86_64 and i586 and cannot
be packaged in any of the other architectures.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-05-27 15:38:42 +01:00
Stefan Schantl
52ebc66bba
hyperscan: New package
...
This package adds hyperscan support to suricata
Fixes #12053 .
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-05-27 14:40:14 +01:00
Stefan Schantl
2348cfffcf
ragel: New package
...
This is a build dependency of hyperscan
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-05-27 14:40:03 +01:00
Stefan Schantl
1a5f064916
colm: New package
...
This is a build dependency of ragel, which is a build dependency of
hyperscan.
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-05-27 14:39:32 +01:00
Stefan Schantl
616395f37c
jansson: Move to core system and update to 2.12
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-05-27 14:39:00 +01:00
Michael Tremer
f6e18df542
Rootfile update
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-05-27 14:37:23 +01:00
Michael Tremer
333125abf8
Merge branch 'toolchain' into next
2019-05-24 06:55:03 +01:00
Michael Tremer
9f0295a512
Merge remote-tracking branch 'ms/faster-build' into next
2019-05-24 06:54:16 +01:00
Matthias Fischer
f225f3ee29
bind: Update to 9.11.7
...
For details see:
http://ftp.isc.org/isc/bind9/9.11.7/RELEASE-NOTES-bind-9.11.7.html
"Security Fixes
The TCP client quota set using the tcp-clients option could be exceeded in some cases.
This could lead to exhaustion of file descriptors.
This flaw is disclosed in CVE-2018-5743. [GL #615 ]"
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-05-24 06:36:55 +01:00
Arne Fitzenreiter
b0d31edbd6
vnstat: fix errormessage at first boot
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-05-21 20:36:16 +02:00
Arne Fitzenreiter
6d37280f3e
configroot: create main/security settings file
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-05-21 15:03:21 +02:00
Arne Fitzenreiter
405f69fc9c
web-user-interface: update rootfile
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-05-21 15:02:54 +02:00
Michael Tremer
6a83dbb451
SMT: Apply settings according to configuration
...
SMT can be forced on.
By default, all systems that are vulnerable to RIDL/Fallout
will have SMT disabled by default.
Systems that are not vulnerable to that will keep SMT enabled.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-05-20 21:30:26 +01:00